First published: Thu Oct 06 2022(Updated: )
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <=2.4.10 | |
Ikus-soft Rdiffweb | =2.5.0-alpha1 | |
Ikus-soft Rdiffweb | =2.5.0-alpha2 | |
Ikus-soft Rdiffweb | =2.5.0-alpha3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3273 is a vulnerability that allows the allocation of resources without limits or throttling in the GitHub repository ikus060/rdiffweb prior to version 2.5.0a4.
CVE-2022-3273 has a severity value of 9.8 (critical).
CVE-2022-3273 affects versions up to and including 2.4.10, 2.5.0-alpha1, 2.5.0-alpha2, and 2.5.0-alpha3 of Ikus-soft Rdiffweb.
To fix CVE-2022-3273, update your Ikus-soft Rdiffweb installation to version 2.5.0a4 or later.
For more information on CVE-2022-3273, you can refer to the following references: [GitHub Commit](https://github.com/ikus060/rdiffweb/commit/b5e3bb0a98268d18ceead36ab9b2b7eaacd659a8) and [Huntr Bounty](https://huntr.dev/bounties/a6df4bad-3382-4add-8918-760d885690f6).